Junglewise Threat Intelligence

CVE-2026-20068: Cisco Snort 3 detection engine denial of service

CVE-2026-20068 · Severity: medium · CVSS 5.8 · Published 2026-03-04

Executive brief

Cisco Snort 3, a network intrusion detection and prevention engine used in multiple security products, contains a flaw in RPC packet parsing. An unauthenticated remote attacker can exploit this by sending specially crafted packets to cause the detection engine to crash and restart, interrupting network traffic inspection and leaving systems temporarily unprotected.

Technical details

The vulnerability stems from incomplete error checking when the Snort 3 detection engine parses remote procedure call (RPC) data. An attacker can send malformed RPC packets through an established connection to trigger the vulnerability. The flaw allows a network-based, unauthenticated DoS attack that causes the Snort 3 engine to unexpectedly restart. This affects multiple Cisco products including Secure Firewall FTD (with Snort 3 enabled), IOS XE devices running UTD Snort IPS Engine, Meraki security appliances, and open-source Snort 3. Cisco has released software updates to address the issue.

Affected products

  • Cisco Snort 3 vulnerable versions documented in fixed software section
  • Cisco Secure Firewall Threat Defense releases with Snort 3 configured
  • Cisco IOS XE Software releases with vulnerable UTD Snort IPS Engine
  • Cisco Catalyst 8000V Edge Software releases with vulnerable UTD
  • Cisco Catalyst 8200 Series Edge Platforms releases with vulnerable UTD
  • Cisco Catalyst 8300 Series Edge Platforms releases with vulnerable UTD
  • Cisco Cloud Services Router 1000V releases with vulnerable UTD
  • Cisco Meraki MX Security Appliances vulnerable Meraki Software releases
  • Cisco Cyber Vision vulnerable releases

Timeline

  • 2026-03-04: disclosed: Cisco Security Advisory published
  • 2026-03-04: patched: Cisco released software updates

References

Related threats